Wireless Access

last person joined: 19 hours ago 

Access network design for branch, remote, outdoor, and campus locations with HPE Aruba Networking access points and mobility controllers.
Expand all | Collapse all

Custom captive-portal certificate in master-local topology

This thread has been viewed 0 times
  • 1.  Custom captive-portal certificate in master-local topology

    Posted Aug 30, 2014 07:16 AM

    Hi Based on this KB https://arubanetworkskb.secure.force.com/pkb/articles/HowTo/R-1544 we will be implementing custom-captive portal certificate on a master & multi-local setup. Can we generate CSR from the master and get the certificate from the CA. Then upload the obtained certificate on the master and all the local controllers?



  • 2.  RE: Custom captive-portal certificate in master-local topology

    EMPLOYEE
    Posted Aug 30, 2014 03:40 PM
    You should do the csr from a server so that you can export the private key.

    Then sign it, import it to the server, then export it with the private key.

    Then import it on the controllers.

    Easiest way is to use a Windows box with IIS or a Linux box with openssl.


  • 3.  RE: Custom captive-portal certificate in master-local topology

    Posted Sep 04, 2014 01:37 AM

    Hi 

     

    Thank you for help. as per this KB.

    https://arubanetworkskb.secure.force.com/pkb/articles/HowTo/R-1207

     

    I can use the CSR generated from master controller, and get the server certificate from the CA. 

     

    then upload and use the same certificate on all controllers, it will work, right? 



  • 4.  RE: Custom captive-portal certificate in master-local topology

    Posted Sep 05, 2014 07:13 AM

    Hi Yogenpartha,

     

    It won't work.

     

    You have two options ::

     

    1. Generate CSR on each controller and get them signed. When CSR is generated on controller; the private key doesn't leave the box (for security reasons). Please see here https://arubanetworkskb.secure.force.com/pkb/articles/HowTo/R-890
    2. Generate CSR outside as mentioned already and get it signed. In this case; we can upload single cert to all controllers as private key isn't locked to the controller where CSR was generated.

    Hope this helps.

     

     



  • 5.  RE: Custom captive-portal certificate in master-local topology

    Posted Sep 17, 2014 09:44 PM

    Hi 

     

    Thank you for reply. Can a public CA, generate a CSR by themselves with the details needed for generating the CSR. I dont know how it works.. 

     

    so that i can use the same certificate on all the OAW controllers? 



  • 6.  RE: Custom captive-portal certificate in master-local topology

    EMPLOYEE
    Posted Sep 18, 2014 03:39 AM
    You should generate the CSR on an external server so that you can export the private key. If you have the private key, you can use the cert on all of your controllers.